Why cyber insurance is getting harder to obtain, and what UK businesses can do about it

Cyber insurance is affordable again, yet many UK firms cannot get covered. The reason is the controls insurers now require, and what to do before your renewal.

Cyber insurance has rarely been cheaper to buy. Global cyber premiums fell again in the second quarter of 2026, the twelfth quarter of decline in a row, according to broker Marsh. On price alone, this looks like a buyer’s market.

So why are more UK businesses finding it hard to get covered? Because the barrier has moved. Insurers are not winning business by dropping their standards. They are competing hardest for the companies that can prove they take security seriously, and turning away, or quietly restricting, the ones that cannot. The first question on the proposal form is no longer what you want to insure. It is how you protect it.

For any business that treats cyber cover as a form to complete when the renewal reminder lands, that shift is the whole story.


What has actually changed?

The market has flipped twice in five years. After ransomware losses spiralled in 2021 and 2022, insurers were paying out faster than they could price for it. Premiums roughly doubled, capacity dried up, and the cover that remained came with far more conditions attached. Discipline has since returned. Insurers tightened who they would take on, buyers improved their defences, claims became more predictable, and rates have been falling for three years.

What never loosened was the entry requirement. The security controls insurers brought in during the hard market to stem their losses have stayed firmly in place. So a business shopping for cover today finds premiums that look affordable sitting behind a proposal form that assumes a level of security maturity many UK firms have not reached.

That gap is well documented. The government’s Cyber Security Breaches Survey 2025 found that only 40% of businesses use two-factor authentication, and just 19% run staff security awareness training. Both sit near the top of every insurer’s checklist. Strengthening them is exactly the work our cybersecurity services exist to do.


Why do insurers keep raising the bar?

Because the loss they fear most has not gone away. Ransomware is still the event that turns a routine claim into a catastrophic one, and it is growing again. The same survey found the share of UK businesses hit by a ransom demand doubled in a year, from under 0.5% to 1%, around 19,000 businesses. Larger organisations are squarely in the firing line: 67% of medium and 74% of large businesses reported a breach or attack in the previous twelve months.

Insurers have also learned not to trust a soft market to last. During 2026, ratings agency S&P Global and the underwriter DUAL both warned that today’s falling prices and looser terms could force a sharp correction, with capacity pulled and underwriting tightened, if claims climb. When that happens, the businesses that already meet the controls keep their cover on sensible terms. The ones leaning on a soft market to carry them are the first to be squeezed.


What controls do insurers now expect to see?

The exact list varies by insurer and by the size of the risk, but the core of it is remarkably consistent. Treat these as the price of entry, not a wish list.

Multi-factor authentication on everything that matters. Email, remote access, VPNs, and administrator accounts. Weak or missing MFA is the single most common reason a proposal is declined or a ransomware claim is later disputed.

Managed detection and response. Insurers want to know that someone, or something, is watching around the clock and can act when an alarm goes off, not just antivirus running quietly on each machine.

Backups you have actually tested. Isolated, ideally immutable copies that ransomware cannot reach, and a restore you have proven works. This is where cyber cover meets business resilience, a core part of how we help clients reduce risk. The backup is only worth what you can recover from it, which is why we cover the detail in our guide to business data backup solutions.

Prompt patching and no unsupported software. Known vulnerabilities in unpatched or end-of-life systems are an easy underwriting decline, and an easy way in for an attacker.

Security awareness training and phishing simulation. People are the way in. Phishing was involved in 85% of the breaches UK businesses reported in 2025. Training is not a poster on the wall; it is regular, measured practice.

We hold ourselves to the same test. Highgate runs phishing simulation and awareness training across our own 160 mailboxes, and captured 334 email security incidents in the first year of doing so.

“The latest simulation came back without a click, which told me I’d made the right call.”  – Paolo Rodia, Services Director at Highgate IT Solutions

A written incident response plan. Insurers increasingly ask to see one. Knowing who does what in the first hour of an incident is the difference between a contained event and a full-blown claim.


What happens if you cannot demonstrate them?

Rarely a flat refusal with no explanation. Far more often, cover arrives with conditions that quietly hollow it out. A ransomware sub-limit set well below your real exposure. A higher excess you have to fund yourself before the policy responds at all. An exclusion for the exact scenario that worried you in the first place. Or a warranty that you fix named gaps before the cover holds.

There is a knowledge problem underneath all of this. The same survey found that one in five businesses do not know whether they hold any cyber cover at all, and only 7% have a standalone cyber policy rather than protection bolted on to a wider business insurance. A bolt-on can be a reasonable start, but it often carries low limits and broad exclusions, and it may not respond the way you assume when an incident actually hits. If you are not sure what you have, that uncertainty is worth resolving before you need it, not after.

Where do you start?

The businesses that renew smoothly are rarely the ones with the largest security budgets. They are the ones who treated the insurer’s proposal form as a fair summary of good practice and worked through it long before they needed to. The controls that earn better terms are the same controls that stop the incident happening in the first place. The policy is the backstop, not the plan.

A good place to begin is an honest look at where you stand against that checklist, and a clear view of how you would recover if the worst happened anyway. If you are also weighing up whether your current IT provider is holding up their end, our guide to how to vet an IT provider is a useful next read. Talk to us about a security review, and we’ll set out exactly where your gaps are and how we’d close them.